ci(release): publish the release bundle to Google Play
Adds Play as a third channel alongside the F-Droid repo and the Codeberg download. It gets its own artifact: bundleRelease produces an AAB from the same source and signing config as the published APK, which is left untouched so the F-Droid reproducibility guarantee is unaffected. The upload runs as a separate trailing job rather than more steps in 'release'. Play is the only channel that can reject a good build for reasons the pipeline cannot see — listing rules, policy review, a track needing manual promotion — and that must surface as one red job beside a release that already shipped, not as a failure of the workflow that shipped it. It also skips cleanly until PLAY_SERVICE_ACCOUNT_JSON exists, so the pipeline keeps working during Play Console setup. fastlane is scoped deliberately to 'supply'. Build and signing stay on Gradle: interposing fastlane there would add a layer able to inject flags into the one build a third party verifies byte-for-byte. What fastlane buys is that fastlane/metadata/android — already the source F-Droid harvests — is exactly what supply consumes, so 'What's New' comes from CHANGELOG.md via the existing sync script for both stores. Listing text is not pushed per release (an accidental overwrite of a live listing is a policy-review event, not a revert), and images are skipped because the committed assets satisfy F-Droid but not Play: the screenshots are 1280x2856 with alpha where Play caps the long edge at 2x the short edge and wants 24-bit, and no 1024x500 featureGraphic exists. The job runs without a container image despite fastlane publishing one: act_runner provides no node inside custom job containers, so checkout and download-artifact cannot run there. Uploads default to the internal track — promotion to production stays a human action, matching the rule that UI releases wait for on-device review. Note that Play App Signing means Play installs and F-Droid installs carry different signatures and cannot update each other; the release key is registered only as the upload key. Documented in docs/RELEASING.md.
This commit is contained in:
11
.gitignore
vendored
11
.gitignore
vendored
@@ -61,5 +61,16 @@ Thumbs.db
|
||||
# KSP
|
||||
.ksp/
|
||||
|
||||
# Google Play Developer API service-account key. Reconstructed in CI from the
|
||||
# PLAY_SERVICE_ACCOUNT_JSON secret and shredded afterwards — never committed.
|
||||
/play-service-account.json
|
||||
|
||||
# fastlane (Play uploader only — see fastlane/Fastfile)
|
||||
/fastlane/report.xml
|
||||
/fastlane/README.md
|
||||
/vendor/bundle/
|
||||
/.bundle/
|
||||
Gemfile.lock
|
||||
|
||||
# Claude Code
|
||||
/CLAUDE.md
|
||||
|
||||
Reference in New Issue
Block a user